zeronetworks / rpcfirewallLinks
☆523Updated 3 months ago
Alternatives and similar repositories for rpcfirewall
Users that are interested in rpcfirewall are comparing it to the libraries listed below
Sorting:
- A repository that maps commonly used attacks using MSRPC protocols to ATT&CK☆336Updated 2 years ago
- A centralized resource for previously documented WDAC bypass techniques☆573Updated last week
- Event Tracing For Windows (ETW) Resources☆397Updated 11 months ago
- Aims to identify sleeping beacons☆627Updated 9 months ago
- Detect and respond to Cobalt Strike beacons using ETW.☆508Updated 3 years ago
- Scan installed EDRs and AVs on Windows☆592Updated 2 months ago
- ☆382Updated 2 years ago
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆287Updated 2 years ago
- ☆253Updated last year
- ☆507Updated last year
- Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for…☆488Updated 2 years ago
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆773Updated last year
- ☆419Updated 3 years ago
- Extracted Yara rules from Windows Defender mpavbase and mpasbase☆461Updated last month
- Sysmon EDR POC Build within Powershell to prove ability.☆226Updated 4 years ago
- A PowerShell armoury for security guys and girls☆470Updated last year
- A C# utility for interacting with SCCM☆654Updated 3 weeks ago
- PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.☆319Updated 4 months ago
- An effort to track security vendors' use of Microsoft's Antimalware Scan Interface☆249Updated 3 years ago
- ☆584Updated 3 months ago
- Cobalt Strike UDRL for memory scanner evasion.☆977Updated last year
- Sysmon-Like research tool for ETW☆364Updated 2 years ago
- Cobalt Strike Beacon configuration extractor and parser.☆156Updated 4 years ago
- ☆204Updated 10 months ago
- ☆786Updated 2 years ago
- A collection of tools to interact with Microsoft Security Response Center API☆101Updated last year
- a tool to help operate in EDRs' blind spots☆758Updated 9 months ago
- PoCs and tools for investigation of Windows process execution techniques☆935Updated last week
- PIC lsass dumper using cloned handles☆593Updated 2 years ago
- Active Directory delegation management tool☆339Updated 2 years ago